ISO/IEC 27001 is an international standard for information security management published by the International Organization for Standardization. It defines the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS) — a structured framework of policies, processes, and controls for managing information security risk.
Key components include:
ISO 27001 certification is awarded following an audit by an accredited certification body. Certification requires periodic surveillance audits and recertification to remain current. Accreditation bodies include ANAB (anab.ansi.org) and the ISO directly (iso.org).
What is SOC 2 Type 2 Certification?
SOC 2 (System and Organization Controls 2) is an auditing framework developed by the American Institute of Certified Public Accountants (AICPA) that defines how service providers should manage and protect client data. A SOC 2 Type 2 certification is issued following an independent audit conducted by a licensed CPA firm, covering an extended period — typically six to twelve months — rather than a single point in time.
The audit evaluates controls across five trust service criteria:
The AICPA sets the standards for SOC 2. Licensed CPA firms accredited by the AICPA conduct the audits. A current SOC 2 Type 2 report documents the results of that audit for the covered period.
Dealerships handle sensitive data across multiple departments — customer personally identifiable information, credit applications, service history, financing records, and data connected to dealer management systems. When a software or service provider has access to any of that data, the dealer has an interest in understanding how that provider manages and protects it.
SOC 2 Type 2 and ISO 27001 are two of the most widely recognized independent frameworks for verifying that a vendor has documented security controls in place. Both involve third-party audits conducted against established standards rather than self-assessment. The primary distinctions are:
Neither framework is universally required for dealership software vendors. Dealers evaluating vendors with access to customer data, DMS feeds, or financial systems may request a current SOC 2 Type 2 report or ISO 27001 certificate as part of their vendor evaluation process.
Dealer Software Success tracks MCP readiness across software and service providers in our AI Provider Rankings as this information becomes available.
If you would like something added to our FAQs page, please use the Contact Us link at the bottom of this page.
Tell us what needs correcting and we'll review it promptly. Fields marked * are required.